GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
GlobalProtect Discussions
GlobalProtect discussions offers topics about our network security for endpoints that protects your organization's mobile workforce. This area is dedicated to GlobalProtect discussions to help you answer questions.
About GlobalProtect Discussions
Welcome to the GlobalProtect discussion area! Here, you can engage in conversations about GlobalProtect, explore new insights, and stay updated on ongoing discussions. Check back regularly for the latest updates and community insights on GlobalProtect.

Discussions

Certificate Chain Requirements from External CA for Global Protect

Hi Everyone, So I'm having issues configuring my GP as it does not allow me to select the server-cert from the TLS/SSL Service profile Window. The server-cert is not even an option to select from within the window itself and when i try to import it from inside the TLS/SSL Service profile window - it imports but errors out saying the cert is inva...

GP7337_1-1738863827766.png
GP7337 by L1 Bithead
  • 1760 Views
  • 3 replies
  • 0 Likes

Resolved! Multple entries for "Allow specified fqdn when Enforce GlobalProtect Connection"

Hi everyone, Could you please help me to figure out what is the right format I should use to add multiple entries for "Allow specified fqdn when Enforce GlobalProtect Connection"? In the following support doc, I can see that I must put space before the wildcard character. Enforce GlobalProtect Connections with FQDN Exclusions Additionall...

Resolved! Users getting authentication error while accessing GP VPN

Hello Team, At one of our locations, users were unable to access GP VPN due to authentication failure. we could see below logs on, how can we find out the root cause, was it delayed response from IDP or Firewall to NTP 'SAML message from IdP "https://sts.windows.net/XXXXXXXXXXXXXXX/" (server profile "SAML-AUTH") was expired already (not_on...

CSOIMGL2 by L0 Member
  • 1349 Views
  • 1 replies
  • 0 Likes

Local and SAML users authentication on the single GP Portal and Gateway

I have a task to use 2 authentication methods - local and SAML on the single GP Portal and Gateway. First check local users and if username not found then check SAML users. As I know authentication sequence isn't supported for SAML. Separating users by OS type isn't way for us because different users (SAML and local) can use the same OS type. Ar...

Global Protect VPN blocks guest OS traffic

Hello all, Using VirtualBox 7 and I assumed that by having NAT network set on my Guest OS that it would work straightforward and I would be able to access services from the VPN that is running on my host OS (win11). First of all the problem happens when VPN is On. When disabled everything works normal. The below remarks are for when the VPN is...

Panagiss by L1 Bithead
  • 1520 Views
  • 2 replies
  • 0 Likes

GlobalProtect App Config Refresh Interval Expected Behavior

Hello everyone, I would like to confirm the specifications of "GlobalProtect App Config Refresh Interval". Is it correct to understand that the above interval is the interval at which the GP Agent goes to the portal to obtain the configuration when it is able to connect to the portal, and that if the GP Agent cannot connect to the portal, this r...

GP Client for MAC device cannot be used normally

Hi all, GP version 6.2.2 Machine: MAC OS When user log in to GlobalProtect on a Mac for the first time, i can enter user1 to log in normally.However, when restart the computer and log in again, i find that the user account has been locked and is displayed as user1 and cannot be modified. we can only enter the password, so the login will fai...

Wildcard Support for Application-based Split Tunnel Question

I was reading this article and it seems like a fairly easy way to split tunnel Microsoft Teams to exclude it from the GlobalProtect VPN. Especially now with new Teams using a product version in the application path. I see the article is written from the perspective of Prisma Access. Any clue if I can use this with standard PAN-OS managed fire...

Resolved! Use "Embedded Browser" within SAML Authentication with the combination PAN-OS 11.2.3-h5 and GP-6.2.7

Hello together, we have the situation that a customer want use the Embedded Browser within his SAML Authentication process. The correspondingly necessary option in the GP-App section within the GP-Gateway configuration is set. But in every SAML Authentication process the default browser is used. Have somebody tried out this combination, contacte...

  • 1684 Posts
  • 68 Subscriptions
Top Solution Authors
Top Liked Authors
Labels